US12608322B2UtilityA1
Techniques of encrypting BMC and bios firmware and data in flash memory
Priority: —Filed: Sep 19, 2023Granted: Apr 21, 2026
G06F 2212/1052G06F 12/1408
37
PatentIndex Score
0
Cited by
26
References
14
Claims
Abstract
In an aspect of the disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus is a BMC. The BMC receives data to be written to a storage. The BMC encrypts the data using a stream encrypt engine to generate encrypted data. The BMC writes the encrypted data to the storage. The BMC receives encrypted data read from the storage. The BMC decrypts the encrypted data using a stream decrypt engine to generate decrypted data. The BMC provides the decrypted data to a component of the BMC.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of operation of a baseboard management controller (BMC), the method comprising:
routing data to be written from a first hardware component of the BMC or a host of the BMC to a storage through a hardware data encrypt/decrypt component positioned in-line between the first hardware component and the storage, wherein the hardware data encrypt/decrypt component is separate from and external to the first hardware component; encrypting the data using a stream encrypt engine of the hardware data encrypt/decrypt component to generate encrypted data; writing the encrypted data to the storage; routing encrypted data read from the storage to the first hardware component through the hardware data encrypt/decrypt component; and decrypting the encrypted data using a stream decrypt engine of the hardware data encrypt/decrypt component to generate decrypted data.
2 . The method of claim 1 , further comprising:
receiving a control command; and providing the control command to the storage without encryption and decryption.
3 . The method of claim 1 , wherein encrypting the data comprises encrypting the data using a unique key associated with the stream encrypt engine.
4 . The method of claim 3 , wherein the unique key is derived from a unique identifier of the BMC.
5 . The method of claim 1 , wherein a size of the encrypted data equals a size of the data received to be written to the storage.
6 . The method of claim 1 , wherein the storage comprises a serial peripheral interface (SPI) flash memory.
7 . The method of claim 1 , wherein the data are a part of firmware of the BMC or a part of firmware of a Basic Input/Output System (BIOS) of a host of the BMC.
8 . A baseboard management controller (BMC) comprising:
a hardware data encrypt/decrypt component positioned in-line between a first hardware component and a storage, wherein the hardware data encrypt/decrypt component is separate from and external to the first hardware component, the hardware data encrypt/decrypt component comprising:
a stream encrypt engine configured to encrypt data to be written to the storage; and
a stream decrypt engine configured to decrypt encrypted data read from the storage;
a memory; and a processing unit coupled to the memory and configured to:
route data to be written from the first hardware component to the storage through the hardware data encrypt/decrypt component including providing the data to the stream encrypt engine for encryption, wherein the stream encrypt engine provides the encrypted data to the storage; and
route encrypted data read from the storage to the first hardware component through the hardware data encrypt/decrypt component including providing the encrypted data to the stream decrypt engine for decryption.
9 . The BMC of claim 8 , wherein the processing unit is further configured to:
receive a control command; and provide the control command to the storage without encryption and decryption.
10 . The BMC of claim 8 , wherein the stream encrypt engine is configured to encrypt the data using a unique key associated with the stream encrypt engine.
11 . The BMC of claim 10 , wherein the unique key is derived from a unique identifier of the BMC.
12 . The BMC of claim 8 , wherein a size of the encrypted data equals a size of the received data to be written to the storage.
13 . The BMC of claim 8 , wherein the storage comprises a serial peripheral interface (SPI) flash memory.
14 . The BMC of claim 8 , wherein the data is a part of firmware of the BMC or a part of firmware of a Basic Input/Output System (BIOS) of a host of the BMC.Join the waitlist — get patent alerts
Track US12608322B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.